# Customizations layered on top of the upstream Fedora COSMIC Atomic manifests. packages: # Fedora integration packages normally provided by the upstream fedora.yaml, # re-added here without Firefox (which is shipped as a Flatpak instead). - fedora-bookmarks - fedora-chromium-config - fedora-flathub-remote - fedora-workstation-backgrounds - fedora-workstation-repositories - fedora-release-cosmic-atomic - toolbox # Smartcard / FIDO2 support for token2-fido-bridge. # token2-fido-bridge itself is installed from a local repo that build.sh # generates from the upstream GitHub release (it is not packaged in Fedora). - pcsc-lite - pcsc-lite-ccid - opensc - libfido2 - fido2-tools - p11-kit - pam-u2f - token2-fido-bridge # Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients). - kanidm-unixd-clients - kanidm-clients # Firefox is intentionally not part of the base system. It is preinstalled as a # per-user Flatpak on first login instead (see flatpaks.list). exclude-packages: - firefox add-files: - ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"] - ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"] - ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"] - ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"] - ["50-token2-fido-bridge.preset", "/usr/lib/systemd/system-preset/50-token2-fido-bridge.preset"] - ["uhid.conf", "/usr/lib/modules-load.d/uhid.conf"] # Kanidm client config and authselect profile sources. - ["kanidm-config", "/etc/kanidm/config"] - ["kanidm-unixd", "/etc/kanidm/unixd"] - ["kanidm-system-auth", "/usr/share/fedora-cosmic/authselect/system-auth"] - ["kanidm-password-auth", "/usr/share/fedora-cosmic/authselect/password-auth"] - ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"] - ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"] postprocess: # The upstream fedora.yaml removes the Google Chrome repo from the Fedora # Third Party repo list. We opt out of that manifest, so replicate it here. # Workaround for https://github.com/coreos/rpm-ostree/issues/5494 - | #!/usr/bin/env bash set -xeuo pipefail sed -i -e '/google-chrome/,+2d' /usr/lib/fedora-third-party/conf.d/fedora-workstation.conf || true # Ensure the first-login script is executable and make sure the # globally-enabled per-user Flatpak unit is picked up. - | #!/usr/bin/env bash set -xeuo pipefail chmod 0755 /usr/libexec/flatpak-user-firstboot systemctl --user --global preset-all # Kanidm PAM/nsswitch integration. Prefer an authselect profile; fall back to # installing the files directly (and dropping the authselect symlinks) if # authselect is unavailable in the compose environment. - | #!/usr/bin/env bash set -xeuo pipefail if ! ( set -euo pipefail authselect create-profile kanidm -b local install -m 0644 /usr/share/fedora-cosmic/authselect/system-auth \ /etc/authselect/custom/kanidm/system-auth install -m 0644 /usr/share/fedora-cosmic/authselect/password-auth \ /etc/authselect/custom/kanidm/password-auth install -m 0644 /usr/share/fedora-cosmic/authselect/nsswitch.conf \ /etc/authselect/custom/kanidm/nsswitch.conf authselect select custom/kanidm --force --nobackup ); then echo "authselect setup failed, installing PAM/nsswitch directly" >&2 rm -f /etc/pam.d/system-auth /etc/pam.d/password-auth /etc/nsswitch.conf install -m 0644 /usr/share/fedora-cosmic/authselect/system-auth /etc/pam.d/system-auth install -m 0644 /usr/share/fedora-cosmic/authselect/password-auth /etc/pam.d/password-auth install -m 0644 /usr/share/fedora-cosmic/authselect/nsswitch.conf /etc/nsswitch.conf fi # Kanidm does not ship an SELinux policy yet; let the unixd daemons run. - | #!/usr/bin/env bash set -xeuo pipefail semanage permissive -a unconfined_service_t || true # Lock down the Kanidm service account token if it was seeded at build time. - | #!/usr/bin/env bash set -xeuo pipefail if [[ -f /etc/kanidm/unixd_token ]]; then chown root:root /etc/kanidm/unixd_token chmod 0600 /etc/kanidm/unixd_token fi